I will audit your amazon eks cluster for security and cost as a US based engineer
About this Gig
NYC-based, US Eastern hours, US company (Crafty Technologies, est. 2007).
Your EKS cluster works. That is not the same as it being safe or economical. Most clusters I review share the same problems: over-permissive IAM roles bound to service accounts, containers running as root because a Helm chart default was never revisited, security groups opened during an incident and never closed, no network policy, and node groups still sized for a load test that ended months ago. None of these page anyone. All of them cost money or carry risk.
This is a fixed-scope, read-only review of one EKS cluster in one AWS account, benchmarked to the CIS Amazon EKS Benchmark and the AWS Well-Architected Framework (Security and Cost). I change nothing.
You get a PDF report: findings ranked Critical/High/Medium/Low with a recommended fix for each, the top quick wins, a cost analysis with estimated savings, and a remediation roadmap.
28 years of enterprise infrastructure delivery in banking, insurance, healthcare and media.
Message me before ordering if you have more than one cluster or account.
Cloud provider:
Amazon Web Services
Expertise:
Configuration
Cloud computing resource:
ELB
•
VPC
•
Security Groups
Other Cloud Computing Services I Offer
FAQ
Will you change anything in my cluster?
No. The review is strictly read-only. You grant a read-only IAM role and a view-only Kubernetes access entry, and remove both when the report is delivered.
How is this different from just running kube-bench?
Scanners list checks. I read the IAM, network, workload and cost picture together, rank findings by real risk to your setup, and tell you what to fix first and what it will cost or save.
Can you fix what you find?
Yes, as a separate fixed-price follow-on: Critical and High findings remediated as reviewable Terraform pull requests, then a re-scan. This review fee is credited toward it.
Where are you based?
New York City area, working US Eastern business hours. You're dealing with a US company, not a subcontracted team.
